Security Questionnaire Mapper
Clause text

GDPR, Regulation (EU) 2016/679: the clauses the register cites

The 7 GDPR, Regulation (EU) 2016/679 clauses that questions are placed on, each with the evidence an assessor asks for and where answers usually fall short.

The requirement lines are our statement of each clause, read against the copy we hold and cited to it.

7 clauses

the families they anchor
GDPR Art. 6 Lawfulness of processing

Process personal data only where at least one lawful basis applies: the data subject's consent, necessity for a contract with the data subject or pre-contractual steps at their request, compliance with a legal obligation, protection of vital interests, performance of a public interest task or exercise of official authority, or legitimate interests that are not overridden by the data subject's interests, rights and freedoms. Public authorities cannot rely on legitimate interests for processing carried out in performance of their tasks. Where the basis is legal obligation or public task, that basis must be laid down in Union or Member State law and the purpose must be determined in it. Before processing for a purpose other than the one collected for, without consent or a legal mandate, assess compatibility against the link between the purposes, the context of collection, the nature of the data, the consequences for the data subject and the safeguards in place.

Evidence an assessor expects: A lawful basis recorded per processing activity, not per system or per department; Legitimate interests assessments showing the interest pursued, the necessity test and the balancing against the data subject's rights; The Union or Member State provision cited where the basis is legal obligation or public task; Compatibility assessments for each secondary use, covering the five factors Article 6(4) names; Evidence that the basis stated to the data subject in the privacy information matches the one recorded internally
Where answers usually fall short: Consent recorded as the basis where the processing would happen regardless of the answer, which makes it neither free nor the real basis; Legitimate interests asserted with no balancing test on file, or a balancing test that never reaches an adverse conclusion for any activity
Source: GDPR, Regulation (EU) 2016/679
GDPR Art. 15 Right of access by the data subject

On request, confirm whether personal data concerning the data subject is being processed and, where it is, provide access to that data together with the purposes, the categories of personal data, the recipients or categories of recipient including any in third countries or international organisations, the envisaged storage period or the criteria setting it, the existence of the rights to rectification, erasure, restriction and objection, the right to lodge a complaint with a supervisory authority, any available information on the source where the data was not collected from the data subject, and the existence of automated decision-making including profiling with meaningful information about the logic involved and its significance and envisaged consequences. Where data has been transferred to a third country, inform the data subject of the Article 46 safeguards relating to the transfer. Provide a copy of the personal data undergoing processing, in a commonly used electronic form where the request was made electronically, free for the first copy and at a reasonable fee based on administrative costs for further copies. The right to obtain a copy must not adversely affect the rights and freedoms of others.

Evidence an assessor expects: The search methodology showing every system, archive and unstructured store searched, and how completeness was assured; A worked response covering all the supplementary information items, not only the copy of the data; The redaction position and the applied redaction log where third party data was withheld, with a reason recorded per redaction; Timeliness records for the last twelve months of requests measured against the one month limit; The source information provided where the data was not collected from the data subject
Where answers usually fall short: Structured database records returned while email, chat, ticketing and free text notes naming the person are never searched; The copy of the data provided with none of the supplementary information the Article requires alongside it
Source: GDPR, Regulation (EU) 2016/679
GDPR Art. 28 Processor

Use only processors providing sufficient guarantees to implement appropriate technical and organisational measures such that the processing meets the Regulation's requirements and protects the rights of the data subject. A processor must not engage another processor without the controller's prior specific or general written authorisation, and under a general authorisation must inform the controller of intended additions or replacements so the controller can object. The processing must be governed by a written contract or other legal act binding the processor to the controller, setting out the subject matter and duration, the nature and purpose, the type of personal data, the categories of data subjects and the controller's obligations and rights, and stipulating that the processor processes only on documented controller instructions including as to transfers, ensures persons authorised to process are under a duty of confidentiality, takes all Article 32 measures, respects the sub-processor conditions, assists the controller in responding to data subject rights requests, assists with Articles 32 to 36, deletes or returns all personal data at the controller's choice at the end of the service and deletes existing copies unless law requires retention, and makes available all information needed to demonstrate compliance and allows for and contributes to audits and inspections. The processor must immediately inform the controller if it considers an instruction infringes data protection law. The same obligations must be imposed on any sub-processor, and the initial processor remains fully liable for the sub-processor's performance. A processor that determines purposes and means is a controller for that processing.

Evidence an assessor expects: A processor inventory reconciled against the vendor register or accounts payable, so no processor is missing from it; The Article 28(3) contract for each processor, checked clause by clause against the eight stipulations the Article names; Due diligence evidence gathered before appointment showing sufficient guarantees, distinct from the signed contract; The sub-processor authorisation position for each processor, the current sub-processor list, and evidence changes were notified; Audit or assurance rights exercised in practice, such as a report reviewed with findings tracked, and end of service deletion certificates
Where answers usually fall short: The processor's own standard terms accepted, which commonly omit the audit right, the deletion choice and the instruction infringement notice; A processor inventory that misses tools adopted directly by individual teams, which is where undocumented processing usually sits
Source: GDPR, Regulation (EU) 2016/679
GDPR Art. 32 Security of processing

Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of processing, and the risk of varying likelihood and severity for the rights and freedoms of natural persons. Those measures include, as appropriate, the pseudonymisation and encryption of personal data, the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services, the ability to restore the availability of and access to personal data in a timely manner after a physical or technical incident, and a process for regularly testing, assessing and evaluating the effectiveness of the technical and organisational measures. Assess the appropriate level of security against the risks presented by the processing, in particular accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to personal data transmitted, stored or otherwise processed. Take steps to ensure that any person acting under the controller's or processor's authority who has access to personal data processes it only on instructions.

Evidence an assessor expects: The security risk assessment per processing activity, expressed as risk to the rights and freedoms of individuals rather than only as risk to the organisation; Encryption and pseudonymisation coverage at rest, in transit and in backup, with the decision recorded where either was judged not appropriate; Restoration testing results showing personal data was actually recovered inside the intended timeframe, with the date and outcome; The regular testing programme Article 32(1)(d) requires: penetration tests, vulnerability scanning and control effectiveness reviews, with findings closed out; Evidence the measures were reassessed after material change in processing, technology or threat
Where answers usually fall short: Risk assessed as impact to the business, so processing that is low risk to the organisation and high risk to individuals attracts weak measures; Backups taken and never restore tested, so the ability to restore in a timely manner is assumed rather than demonstrated
Source: GDPR, Regulation (EU) 2016/679
GDPR Art. 33 Notification of a personal data breach to the supervisory authority

On becoming aware of a personal data breach, notify it to the competent supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons; a notification made later than 72 hours must be accompanied by the reasons for the delay. A processor must notify its controller without undue delay after becoming aware of a breach. The notification must at least describe the nature of the breach including, where possible, the categories and approximate number of data subjects and of personal data records concerned, give the name and contact details of the data protection officer or other contact point, describe the likely consequences, and describe the measures taken or proposed including any measures to mitigate adverse effects. Information may be provided in phases where it cannot all be given at once. Document every personal data breach, including the facts, its effects and the remedial action taken, so the supervisory authority can verify compliance with this Article.

Evidence an assessor expects: The internal breach register covering all breaches including those assessed as not notifiable, with the risk assessment recorded for each; The awareness timestamp per incident and the basis for it, since the 72 hours runs from awareness and not from confirmation or containment; Notifications as submitted, checked against the four content elements Article 33(3) requires; The methodology used to decide notifiability, and evidence it was applied rather than the decision reached first and documented after; Processor contract terms requiring notification without undue delay, and the notification times actually achieved
Where answers usually fall short: The awareness clock started at the end of the investigation rather than at the point of reasonable certainty that a breach had occurred; Breaches judged not notifiable with no documented assessment, leaving nothing for the authority to verify under Article 33(5)
Source: GDPR, Regulation (EU) 2016/679
GDPR Art. 44 General principle for transfers

Transfer personal data undergoing processing, or intended for processing after transfer, to a third country or an international organisation only where the conditions laid down in Chapter V are complied with by the controller and the processor, including for onward transfers from that third country or international organisation to another third country or international organisation. Apply all the provisions of Chapter V so that the level of protection of natural persons guaranteed by the Regulation is not undermined.

Evidence an assessor expects: A transfer register listing every transfer with the destination country, the recipient, the data categories and the Chapter V mechanism relied on; The onward transfer position for each recipient, showing what the recipient may do with the data and under which mechanism; Evidence that remote access from a third country was assessed as a transfer alongside physical movement of data; The reasoning that the level of protection is not undermined by the arrangement as a whole, not only by the chosen instrument
Where answers usually fall short: Remote support access, cloud administration and follow the sun operations from third countries never recognised as transfers at all; The transfer register recording the contracting entity's location rather than the locations the data can actually be accessed from
Source: GDPR, Regulation (EU) 2016/679
GDPR Art. 46 Transfers subject to appropriate safeguards

In the absence of an adequacy decision, transfer personal data to a third country or an international organisation only where the controller or processor has provided appropriate safeguards and on condition that enforceable data subject rights and effective legal remedies are available. Safeguards requiring no specific authorisation are a legally binding and enforceable instrument between public authorities or bodies, binding corporate rules under Article 47, standard data protection clauses adopted by the Commission, standard clauses adopted by a supervisory authority and approved by the Commission, an approved code of conduct together with binding and enforceable commitments from the recipient to apply the safeguards including as to data subject rights, or an approved certification mechanism with the same commitments. Subject to authorisation from the competent supervisory authority, safeguards may also be provided by contractual clauses between the parties or by provisions inserted into administrative arrangements between public authorities that include enforceable and effective data subject rights.

Evidence an assessor expects: The executed instrument for each transfer, with the modules, annexes and schedules of technical and organisational measures actually completed rather than left blank; The transfer risk assessment examining the destination's law and practice, in particular public authority access, and the conclusion on whether the safeguards are effective there; The supplementary measures adopted where that assessment found the instrument alone insufficient, and evidence they are in place; Supervisory authority authorisation where ad hoc contractual clauses or administrative arrangements are relied on; Evidence that data subjects can in practice exercise the rights the instrument confers, such as an operable third party beneficiary route
Where answers usually fall short: Standard clauses signed with the annexes unfilled, so the data, the purposes and the security measures the clauses are meant to bind are left undefined; No assessment of destination law and practice, so the clauses are relied on in a jurisdiction whose law makes them unenforceable
Source: GDPR, Regulation (EU) 2016/679